Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T11F03123502352A372B0709F6B4708FAE75D9B35DE60BCC5453FC0A5A5FDFC808969AA4 |
|
CONTENT
ssdeep
|
768:IR5GH1G8mgg5M6PADf+/MbLXbYMbFnbYzbHGQJWTtBV1T11vRLYLTVlru+9LWoBB:4QsM6PALr/9RSatBLTrvMJLld |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
a5a5d15c5878daa6 |
|
VISUAL
aHash
|
00677747030040ec |
|
VISUAL
dHash
|
96ceee9ec6608698 |
|
VISUAL
wHash
|
427f77473700e0ec |
|
VISUAL
colorHash
|
38000030000 |
|
VISUAL
cropResistant
|
96ceee9ec6608698 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 14 techniques to evade detection by security scanners and make reverse engineering more difficult.